When Someone Clicks: Five Security Awareness Measures for Municipalities
By Huda Ali
Security Operations Manager, ISA Cybersecurity
October is Cyber Security Awareness Month, and for many municipalities that means a fresh round of awareness training. It is also a good moment to ask a harder question: when a convincing phishing email gets through, will your staff tell you? The measures at the end of this post will help you answer that question. And best of all, you can start on all of them with the training program you already run.
For years, security awareness training taught staff to spot the signs of a phishing email: spelling mistakes, generic greetings like "Dear valued customer," and a sender address that was slightly off. That training did its job, and staff got good at catching them. But those red flags aren’t as common anymore: the Canadian Centre for Cyber Security reports that attackers are using AI to produce more convincing phishing faster and at greater scale.
Municipalities face their own version of this. Council agendas, minutes, staff directories, tenders, and budgets are public by design. An attacker can read them and write an email that names a real supplier, references a tender that closed last week, and asks finance to update banking details before the next payment run. That message may contain nothing for a trained eye to catch.
Everyone clicks eventually
With messages this convincing, chances are that someone on staff will eventually click. Risk managers will recognize what matters next from near-miss reporting: a slip reported early can be contained, while one kept quiet tends to surface later at greater cost. A staff member who reports a click within minutes gives IT time to reset a password, block a sender, or stop a payment before it leaves.
Why people stay quiet
In my work running and monitoring security awareness programs, I find the people who stay silent are usually worried about looking careless, or about crying wolf over something harmless. So they delete the email, get on with their day, and the organization loses sight of what happened.
Reassurance, repeated often, changes that. Leadership needs to say it plainly: these attacks are sophisticated, anyone can be fooled, and nobody is blamed for an honest mistake.
Five metrics to track:
- Report rate: how many staff flag a suspicious message, including ones they've already clicked. Give staff one obvious, low-effort way to report.
- Time to report: minutes from delivery to first report. A quick reply to every report encourages staff to speak up sooner the next time.
- Repeat clickers: are the same people clicking in every simulation? Treat a pattern as a cue for private, one-on-one coaching and support.
- Verification behaviour: do staff call back to a trusted number, or speak to someone directly, before acting on unusual email requests? Set a dollar threshold for any payment or banking change needs that confirmation.
- Role-based risk: are finance, HR, and executive assistants tested on the attacks aimed at them? This fall, include temporary election staff for the municipal elections on October 26, who may not go through normal onboarding.
Completing awareness training is a strong first milestone. Building a culture where people speak up after a mistake is the next one. If you do one thing this month, thank the next person who reports a click. In my experience, it won't be the last report you get from them.
ISA Cybersecurity has delivered cybersecurity services to Canadian organizations for more than three decades. To learn more about building a security awareness program, visit the ISA Cybersecurity security awareness page or contact info@isacybersecurity.com. ISA Cybersecurity also supports LAS' innovative CIMOM program for incident response.



